VAPT Services in Delhi · Government, PSU & Ministry
CERT-In empanelled VAPT for central government, PSUs, ministries and Delhi-NCR fintech — GeM-listed, submission-format reporting.
How a Macksofy vapt engagement runs in Delhi NCR.
Delhi VAPT is overwhelmingly a government and PSU procurement story — and the Indian central-government cybersecurity buyer is a fundamentally different customer from a private-sector BFSI buyer. Tendering routes through GeM (Government e-Marketplace), the Central Public Procurement Portal (CPPP) or the Defence e-Procurement portal where applicable. The buyer asks for a CERT-In empanelled vendor letter, the latest empanelment certificate, a GeM-listed vendor seller-ID, the ISO 27001:2022 and ISO 9001:2015 certificates, and a list of comparable central-government and PSU engagement experience. Macksofy carries all of these and has delivered VAPT engagements to central-government departments, public-sector banks, defence-adjacent organisations and Aadhaar ecosystem actors.
Central-government VAPT scoping has its own shape. The asset inventory typically includes a citizen-facing portal (often hosted at *.gov.in, sometimes at *.nic.in for NIC-hosted workloads), a Bhashini-translated regional-language frontend, a Bharat-Aadhaar-authentication layer (AUA / KUA for Aadhaar-enabled identity verification, DigiLocker integration, eKYC API consumption), an API-gateway-of-India (APIGW) layer for inter-ministry data exchange, and a back-office mainframe or commercial-banking platform behind it. We map each component to its specific MeitY / CERT-In control set and crosswalk to the National Cyber Security Coordinator (NCSC) office's expectations where applicable.
The Bharat / Aadhaar / DigiLocker / API-gateway-of-India scope is unique to Delhi and a Macksofy strength. Aadhaar-AUA / KUA VAPT requires UIDAI-aligned testing methodology — biometric-replay resistance, e-KYC consent-flow integrity, virtual-ID handling, the authentication-API rate-limit and the audit-log evidence requirement under the Aadhaar Authentication Regulations 2016 (as amended 2024). DigiLocker integration testing checks the OAuth scope handling against MeitY's DigiLocker partner-onboarding checklist. APIGW-of-India testing checks the inter-ministry consent-and-purpose-binding layer that MeitY rolled out under the Digital India ecosystem.
PSU bank VAPT in Delhi is a hybrid — RBI's regulatory expectations (Cyber Security Framework, MD-ITGRC) combined with the Department of Financial Services (DFS) circular cadence and the Comptroller and Auditor General of India (CAG) audit overlay. PSU banks are unusual because the IT estate is heterogeneous (Finacle and BaNCS coexisting, legacy mainframe-RACF still in production, branch-network spread across 4,000-15,000 nodes), the procurement cycle is long, and the audit-committee oversight is split between the bank's board and the DFS as the majority shareholder. We size proposals accordingly — fixed-fee SoW with explicit milestone-based payments tied to CAG audit cycles, and a separate inspection-defence retainer for the DFS / RBI thematic-review cycle.
Defence-adjacent and ministry-adjacent VAPT engagements have additional handling requirements — sometimes a security-clearance-equivalent for senior consultants, sometimes a no-cloud-data-transfer clause, sometimes an Indian-passport-only consultant requirement, and almost always an Indian-soil-data-residency requirement that we honour by default. Macksofy maintains an Indian-soil-only delivery option (no foreign-soil data egress) for these engagements, with attestation that satisfies the procuring department's information-security policy.
Delhi-NCR fintech VAPT is the second buyer segment — different methodology, same firm. Delhi-NCR (especially the Connaught Place / Karol Bagh / Saket / South Extension corridor and the parts of Gurugram and Noida that fall under 'Delhi' in informal procurement language) hosts a layer of fintech, lending, payments and BNPL operators that buy VAPT under RBI master directions. The methodology is the same as our Mumbai BFSI VAPT — the difference is procurement (faster, CTO-and-AppSec-lead signoff) and onsite cadence (Connaught Place walk-in, Karol Bagh / Saket inside two hours, Noida and Gurugram via the Yamuna Expressway or DND).
GeM tendering reality matters. Most central-government engagements close via GeM's reverse auction or BoQ-based bidding. Pricing transparency, the GeM seller-ID, the empanelment certificate and the comparable engagement experience are the four levers that decide the L1 outcome. Macksofy maintains a Delhi-resident bid-desk for active GeM tender response within the portal's 7-21 day windows. Procurement on PSU engagements is slower (3-6 months from RFP to PO) but the engagement length is longer (12-18 months from initial VAPT to follow-on retest cycles) so the lifetime value of a PSU-bank or ministry relationship is high.
Onsite cadence is dictated by Delhi geography. Connaught Place, ITO and the central-government secretariat belt are walk-in same day from Aerocity. Saket, South Extension and the ministry-adjacent zones inside the ring road are within 90 minutes. Noida (Sectors 16, 18, 62) and Greater Noida are via Yamuna Expressway in 60-90 minutes. Gurugram (Cyber City, DLF) is via NH-48 in 60-75 minutes. PSU bank head-office visits in Connaught Place or Bhavan-area secretariat addresses are walk-in. For multi-quarter ministry engagements we maintain a Delhi-resident lead consultant.
Five phases. Delhi NCR timeline.
Every Macksofy vapt engagement in Delhi NCR runs through the same phased protocol — adapted to Delhi NCR-specific procurement, regulator and delivery realities.
- GeM / CPPP / Defence e-Procurement bid response with empanelment certificate, seller-ID and comparable engagement list
- Joint kickoff with the procuring department's IT secretary or DGS&D representative
- Indian-soil-only delivery attestation and Indian-passport-only consultant deployment where required
- MeitY / NCSC office submission-format reporting selected at kickoff
- Citizen-portal, regional-language frontend, Aadhaar AUA / KUA, DigiLocker and APIGW component inventory
- PSU bank Finacle / BaNCS / RACF inventory reconciliation with the bank's IT estate
- External attack-surface mapping limited to Indian-soil tooling (no foreign-soil data egress)
- MeitY / CERT-In / NCSC control crosswalk to the asset inventory
- Biometric-replay resistance, eKYC consent-flow integrity and virtual-ID handling per UIDAI methodology
- Aadhaar authentication-API rate-limit and audit-log evidence under Authentication Regulations 2016
- DigiLocker OAuth scope handling against MeitY partner-onboarding checklist
- APIGW inter-ministry consent-and-purpose-binding layer testing with Digital India ecosystem mapping
- MeitY / NCSC submission-format report with control-by-control crosswalk
- PSU bank RBI CSF + DFS circular + CAG audit overlay reconciliation document
- Department-specific information-security-policy alignment annex
- Indian-soil-only delivery attestation signed by Macksofy authorised signatory
- Re-test of every Critical and High inside the procurement-defined remediation window
- DFS / RBI thematic-review inspection-defence retainer for PSU banks
- CAG audit-cycle milestone payment release per the PO terms
- Ministry-side post-engagement risk-register sync where the department maintains one
Which Delhi NCR verticals we deliver VAPT for.
Central government departments
Citizen-portal, regional-language frontend, Aadhaar AUA / KUA and APIGW scopes — MeitY / NCSC submission-format reporting.
Public-sector banks
PSU bank Finacle / BaNCS estates — RBI CSF + DFS circular + CAG audit overlay reconciliation.
Defence-adjacent organisations
Indian-soil-only delivery, Indian-passport-only consultants and security-clearance-equivalent senior bench.
Aadhaar ecosystem actors
AUA / KUA / Sub-AUA entities — UIDAI methodology, Authentication Regulations 2016 evidence, virtual-ID handling.
Delhi-NCR fintech & lending
Connaught Place / Karol Bagh / Saket fintech — RBI master direction VAPT with fast CTO-and-AppSec-lead signoff.
State PSUs (Delhi Govt)
Delhi Government IT department and DJB / DTC-adjacent IT estates — state-procurement-portal VAPT with MeitY format.
The Delhi NCR deliverable pack.
Every Delhi NCR vapt engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.
- VAPT report in CERT-In empanelled + MeitY / NCSC submission format with department-specific control crosswalk
- Aadhaar AUA / KUA Authentication Regulations 2016 evidence pack where in scope
- DigiLocker partner-onboarding checklist coverage where DigiLocker integration is in scope
- APIGW consent-and-purpose-binding layer testing memo for Digital India ecosystem actors
- PSU bank RBI CSF + DFS + CAG overlay reconciliation document
- Indian-soil-only delivery attestation signed by Macksofy authorised signatory
- GeM-portal-compatible bid response and engagement closure documentation
- Free re-test of every Critical and High inside the procurement-defined remediation window
A Delhi NCR vapt case study.
End-to-end VAPT — citizen-portal (Hindi + 8 regional-language Bhashini frontends), Aadhaar AUA / KUA layer, DigiLocker OAuth integration, APIGW-of-India inter-ministry consent layer; Indian-soil-only delivery; 8-week engagement
Six Aadhaar AUA authentication-API rate-limit gaps closed pre-disclosure; two DigiLocker OAuth scope-handling issues closed in coordination with MeitY's DigiLocker team; one APIGW consent-and-purpose-binding bypass closed; report accepted by the ministry's IT secretary on first read and submitted to CERT-In without clarification request.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions Delhi NCR buyers ask before signing.
Other Macksofy engagements in Delhi NCR.
Same engagement, other Macksofy metros.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
